[62284] in North American Network Operators' Group
Re: Root Server Operators (Re: What *are* they smoking?)
daemon@ATHENA.MIT.EDU (Todd Vierling)
Wed Sep 17 09:29:50 2003
Date: Wed, 17 Sep 2003 09:27:13 -0400 (EDT)
From: Todd Vierling <tv@duh.org>
To: Paul Vixie <vixie@vix.com>
Cc: nanog@merit.edu
In-Reply-To: <g37k48hvzo.fsf@sa.vix.com>
Errors-To: owner-nanog-outgoing@merit.edu
On Wed, 17 Sep 2003, Paul Vixie wrote:
: > Anyone have a magic named.conf incantation to counter the verisign
: > braindamage?
:
: zone "com" { type delegation-only; };
: zone "net" { type delegation-only; };
What's to stop VRS from countering with:
*.com. IN A <ipaddr>
*.com. IN NS <letter>.gtld-servers.net.
? (Yup, then there's checking SOA, but there's always the chance that they
can synthesize that too, and move the A record inside it.)
Downward spiral, here we come...! 8-)
--
-- Todd Vierling <tv@duh.org> <tv@pobox.com>